logo

Dark Web Profile: Andariel

ID: ad7c6d74-ccf6-560c-a736-0d015f6cb4bf

STIX ID: report--ad7c6d74-ccf6-560c-a736-0d015f6cb4bf

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-02-27

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Andariel is profiled as a North Korea–linked APT operating under the Reconnaissance General Bureau that blends state-directed espionage with financially motivated ransomware and cryptocurrency theft. The report outlines primary targets (defense, aerospace, nuclear, healthcare, finance), common initial access vectors (vulnerability exploitation, spear-phishing, watering holes), credential-focused lateral movement, data staging/exfiltration practices, notable malware families (Maui, DTrack, TigerRAT, etc.), and recommended mitigations such as patch management, MFA, network segmentation, EDR, and immutable backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.